7.2
CVSSv2

CVE-2007-3530

Published: 03/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHPDirector 0.21 and previous versions stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.

Vulnerable Product Search on Vulmon Subscribe to Product

phpdirector phpdirector

Exploits

PHPDirector <= 021 (SQL injection/Upload SHELL) Remote Vulnerabilities WEB APP: PHPDirector 021 SITE: wwwphpdirectorcouk/site/ DORK: "Powered by PHP Director" AUTHOR: Kw3rLn [ teh_lost_byte[at]YaHoO[d0t]Com ] * Romanian Security Team [Ethical Hacking] - hTTp://RSTZONEnET DESCRIPTION: - SQL injection in $id of videosphp ...